I’m following this topic and the one cross-linked by @unic3rn with interest. This issue would appear to be qualitatively different from the other one, as here the user’s AV software has explicitly flagged the domain in question as malicious. A couple of questions arise:
-
Could the documentation be improved to explain that it is normal to see Tor Browser connecting to randomly generated domains on certain ports? This point is more relevant to the cross-linked issue.
-
Is there a safe and easy way for a user to check if any given domain flagged by AV software is a legitimately created obfuscated relay address, as helpfully explained in this comment? Do such domains belong to a deterministic pool, which could be checked against - e.g. at torproject.org, for example?
The fact that Tor Browser does connect to randomly generated domains seems to be an ideal cover for an attacker who wants to craft a maliciously modified Tor Browser package of the kind @Lind has referred to above. In this case it would seem very important to determine if the domain in question is legitimate or not. If it is malicious and the user did download Tor Browser properly it could point to a wider infection on the user’s machine. In this case simply reinstalling TB may not be sufficient to fix the problem. Anyway, it will be interested to find out if a reinstall does fix the issue.